W3 Total Cache - Information Disclosure (CVE-2024-12008)
Description
The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may contain nonce values that can be used in further CSRF attacks. Note: the debug feature must be enabled for this to be a concern, and it is disabled by default.
psychologyCrowdSec Analysis
CVE-2024-12008 is an information disclosure vulnerability in the W3 Total Cache plugin for WordPress, affecting all versions up to 2.8.1. When the debug feature is enabled, unauthenticated attackers can access a publicly exposed debug log file, potentially revealing sensitive information such as nonce values. This exposure could facilitate further attacks, including cross-site request forgery (CSRF), if exploited.
CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.
CrowdSec network observations suggest that most exploitation of CVE-2024-12008 involves focused reconnaissance to identify viable targets. Attackers typically tailor their campaigns based on system exposure and configuration. It is unlikely that a given attack is accidental. Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2024-12008. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.
Attackers exploit this vulnerability by directly accessing log files such as /wp-content/cache/log/000000/pagecache.log and /wp-content/cache/log/000000/minify.log, exposing sensitive information from W3 Total Cache plugin debug logs. These endpoints are targeted to retrieve data that may aid in further attacks, such as nonce values or credentials.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2025-01-14 |
| Rule Released | 2026-06-24 |
| CrowdSec First Seen | 2026-06-25 |